Skip to main content

Search...

Nudging for Security: Making the Secure Choice the Easy One

Nudging for security starts where most attacks start: human error. Secure defaults, opt-out 2FA and password meters guide users without forcing them.

• • Updated: • 9 min read
Cover of the expert talk on 'Nudging for Security: Making the Secure Choice the Easy One' with Erlijn van Genuchten and Richard Seidl.

Nudging in security means guiding users toward secure behavior through the way software interfaces are designed, without forcing them. Typical tools are secure default settings, clear password strength indicators and automatic locks. The approach is called Security by Behavioral Design and starts as early as the design process.

Key Takeaways

  • Most successful cyberattacks don’t start with a technical vulnerability but with a human error, such as a click on a manipulated link.
  • Nudging in security means making the secure behavior the easiest option without forcing anyone: users who don’t actively decide otherwise end up with the secure setting.
  • Making two-factor authentication opt-out instead of opt-in raises the usage rate considerably, because most users never change default settings.
  • Security by Behavioral Design means building behavioral nudges in during the design phase, not once the application is finished, so usability and security can be improved together.

People Are the Most Common Way In for Attackers

Most successful cyberattacks don’t start with a technical vulnerability. They start with a human error. Erlijn van Genuchten estimates that around 85 percent of attacks get in through people. In other words, the vast majority.

A typical sequence: an email invites the victim to click a link, enter a username and password or download malware. Getting in always requires the targeted person to do something. That is exactly why closing technical gaps is not enough.

Experts often underestimate the human side of security. Pentesters like Erlijn van Genuchten focus on technical vulnerabilities, usually in websites. But if you want to prevent human error, you also have to make the human factor as strong as possible.

Why Even Savvy Users Fall for It

Lack of knowledge is only one end of the scale. People whose jobs have nothing to do with cybersecurity naturally don’t know much about it and have little reason to train up. The less people know, the easier it is for attackers.

At the other end are very capable attackers who write carefully crafted emails. Even people who know what to look for fall for them. Then there’s everyday life. Friday afternoon, stressed, in a hurry to get home: even a smart person stops paying close attention and clicks on something.

AI has raised the level of attacks. Phishing emails used to give themselves away with poor grammar. Today some are so well written that even trained eyes have to check the links.

One especially nasty variant uses characters that are easy to mix up. In some fonts, a lowercase “l” looks just like a capital “I”. That makes it possible to build a fake address that is almost impossible to tell from the real one with the naked eye.

What Nudging Means in Security

A nudge gives users a gentle push in the secure direction without forcing them. The idea comes from fields such as marketing and sustainability and carries over well to security decisions.

The key is that nobody is forced. Software makes the secure choice easy, so users are more likely to make it. Anyone with good reasons can still pick the less secure option. But people who don’t know much about it, or don’t want to think about it, are more likely to end up with the secure one. That alone is a big gain.

This closes exactly the gap that training alone can’t: people who have neither the interest nor the time to deal with security still end up with a better default.

Security Nudges Everyone Knows

Nudges are already built into everyday software. Three mechanisms show the principle especially clearly.

Automatic lock. Your smartphone locks itself after a short time without use. Security happens without anyone doing anything, nobody has to press a button. If you don’t want it, you can switch the lock off. By default, it’s on.

Opt-in versus opt-out. A checkbox you have to tick is an opt-in. A checkbox you have to untick is an opt-out. For two-factor authentication, that means: if it’s enabled by default and has to be switched off actively, far more people use it than if they had to click through the settings to turn it on.

Password strength indicator. When you create a password, it gets rated as “weak”, “medium” or “strong”, often in red, orange or green. That nudges people toward a stronger password without requiring one. As long as the minimum rules are met, the weaker password is still allowed. But the display shifts the choice.

Cutting down helps with security settings, too. Instead of ten options, three are often enough, clearly explained in plain language. Someone choosing between three clear options decides better than someone who can no longer tell ten options apart.

Software Can Warn Against Social Engineering

When an email can no longer be recognized as a scam, software can protect the next step. Browsers, for example, warn you when you’re about to visit a suspicious site.

An example: if you type “googIe.com”, with a capital “I” in place of the lowercase “l”, the browser shows a warning and asks whether you meant “google.com”. It knows that most people want to go to Google, not to the disguised copy. You can still go to the wrong site, but you’re warned before you enter any data.

With a clumsy fake site, the difference is obvious right away. It gets dangerous when someone rebuilds the real site faithfully. Then the warning is the last visible line of defense.

Security by Behavioral Design: Nudges Belong in the Blueprint

Nudges belong in the early stages of development, not in a retrofit. Erlijn van Genuchten takes the well-known principle of Security by Design applies it to behavior and calls it Security by Behavioral Design.

“When you draw the blueprint of the software, at the point where you consider the technical security aspects, you should already bring in the behavioral aspects as well.”

(Erlijn van Genuchten)

In practice, this means that if you’re doing usability testing on the user interface anyway, you can test the nudges along with it. That lets you check early how users react and whether the nudge works. It’s more effective and more user-friendly than retrofitting the mechanisms into a finished application.

How to Measure Whether a Nudge Works

Whether a nudge works can be checked with logging and simple comparisons. For opt-in versus opt-out, a look at new sign-ups is enough: how many people enable two-factor authentication when they have to switch it on themselves, and how many keep it when they would have to switch it off? The difference shows directly whether the default makes a difference.

Not every mechanism is equally easy to measure. Passwords are stored as hashes, so you can’t reliably read the strength of what was entered. For many other cases, database filters and simple statistics are enough.

Usability and Security Don’t Have to Clash

The constant tension between convenience and security doesn’t go away, but many nudges ease it. Often they even make life easier for users, because a secure default is already in place or the software makes the judgment call instead of leaving it to them.

The automatic lock is the clear example: more security without extra effort. With two-factor authentication, on the other hand, the extra code can be a nuisance. Both exist side by side.

If you test and refine nudges early, you can make usability and security strong at the same time instead of playing one off against the other. That is what Security by Behavioral Design is really about.

Frequently Asked Questions

How often does a successful cyberattack begin with human error rather than a technical vulnerability?

People are the most common point of entry. Erlijn van Genuchten estimates that about 85 percent of attacks enter through human interaction. Gaining access always requires some action on the part of the victim: clicking a link, entering a username and password, or downloading malware. Closing technical vulnerabilities is therefore not enough.

Why do even experienced users fall for phishing emails?

Knowledge is only one side of the coin. There are highly skilled attackers who craft precisely worded emails, and AI has raised the bar even further: poor grammar is no longer a telltale sign. Add to that the demands of everyday life. On a Friday afternoon, under stress, even an experienced person may stop paying close attention and click on something without thinking.

How does a “nudge” differ from a mandatory security policy?

A nudge avoids coercion. The software makes the secure choice easy, so users are more likely to make it, but those who have good reasons can still choose the insecure option. The benefit lies with people who have no interest or time to deal with security: they automatically end up with the better default setting.

Does enabling two-factor authentication by default make a difference?

Yes, the adoption rate increases significantly. A checkbox you have to select is an opt-in; one you have to deselect is an opt-out. If two-factor authentication is enabled by default and must be actively disabled, far more people use it than would switch it on themselves in the settings. Most people never change the default settings.

Can a password strength indicator prevent weak passwords?

No. The rating as weak, medium, or strong (often displayed in red, orange, or green) encourages users to choose a stronger password, but it doesn’t force them to do so. As long as the minimum guidelines are met, a weaker password remains an option. The display merely influences the choice. It’s difficult to measure the effect because passwords are stored as hashes.

What good are browser warnings for fake web addresses?

They provide a safety net at the point where the email itself can no longer be identified as a scam. If someone enters an address like googIe.com, where a capital “I” takes the place of the lowercase “l,” the browser asks if they meant to type google.com. The path to the wrong site remains open, but the warning appears before any data is entered.

When should behavioral nudges be planned into software development?

Right from the blueprint stage, at the same point where technical security aspects are taken into account. Erlijn van Genuchten calls this approach “Security by Behavioral Design.” Anyone conducting usability testing on the user interface anyway can test the nudges at the same time and check early on whether they’re effective. Mechanisms squeezed into a finished application after the fact are less effective.

Does greater security always mean more effort for users?

No. Many nudges resolve the conflict between convenience and security because a secure default setting takes effect or the software makes the decision for the user. The automatic screen lock provides greater security without any user action. With two-factor authentication, on the other hand, the additional code remains inconvenient. Both coexist, and the underlying conflict does not disappear entirely.

Share this page